Whitebox Scan credits are organization-wide. They are separate from Code
Review seats, trials, and pooled PR/MR review limits.
How credits work
Estimate first
Hacktron estimates the credit cost from the selected repositories and scope.
Estimation does not deduct credits.
Start with enough balance
Starting the scan deducts the estimated credits from the organization’s
Whitebox Scan credit balance. Internal unlimited organizations show
unlimited credits and are not charged.
Buy credits
Organization owners can buy Whitebox Scan credits. If a member reaches checkout without enough credits, Hacktron asks them to contact an owner to top up the balance. Owners need a saved payment method before purchasing credits. If there is no payment method on file, the checkout flow prompts the owner to add one first, then opens the credit purchase modal. Organization owners can buy credits from Billing or from the Whitebox Scan checkout step when the organization does not have enough credits.Add a payment method
If the organization does not have a payment method, add one before buying
credits.
Insufficient credits
If the organization does not have enough credits for the estimate, the scan will not start. To continue:- Reduce the scope and run a new cost estimate.
- Buy enough credits from Billing.
- Start the scan again after the balance covers the estimate.
402 Payment Required when a scan cannot start because the
organization has insufficient Whitebox Scan credits.
Refunds and cancellations
If a started scan cannot launch successfully after credits are deducted, Hacktron attempts to refund those credits automatically. Failed and stopped scans can show refunded credits in the scan details and transaction history. For Stripe purchase refunds, Hacktron applies the matching credit clawback to the organization balance. If the refunded credits have already been spent, the balance can become negative until the organization tops up again.Related docs
Trigger a Whitebox Scan
Start Whitebox Scans from the REST API and handle insufficient-credit errors.